Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Man, once a year the same BS. JWT in an secure HTTP only cookie are perfectly fine, not less secure then a regular a regular session id, but indeed give you the advantage being able to be stateless!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: